CVE-2005-3908 Information

Description

Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0 and other versions before 5.0.2 allows remote attackers to inject web script or HTML via the query parameter.

Reference

http://pridels0.blogspot.com/2005/11/amazon-shop-500-xss-vuln.html http://secunia.com/advisories/17750 http://www.attrition.org/pipermail/vim/2007-May/001603.html http://www.osvdb.org/21371 http://www.securityfocus.com/bid/15634 http://www.vupen.com/english/advisories/2005/2630

Share on: